Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-m349-rc55-q5w8

Опубликовано: 02 авг. 2026
Источник: github
Github: Не прошло ревью
CVSS3: 4.3

Описание

The Clever Mega Menu for Visual Composer WordPress plugin through 1.0.1 does not perform a nonce or capability check in an AJAX action that updates navigation menu item metadata, allowing any authenticated user, including Subscribers, to overwrite menu item content and settings that are rendered in the site's public navigation.

The Clever Mega Menu for Visual Composer WordPress plugin through 1.0.1 does not perform a nonce or capability check in an AJAX action that updates navigation menu item metadata, allowing any authenticated user, including Subscribers, to overwrite menu item content and settings that are rendered in the site's public navigation.

EPSS

Процентиль: 8%
0.0018
Низкий

4.3 Medium

CVSS3

Дефекты

CWE-284

Связанные уязвимости

CVSS3: 4.3
nvd
около 1 месяца назад

The Clever Mega Menu for Visual Composer WordPress plugin through 1.0.1 does not perform a nonce or capability check in an AJAX action that updates navigation menu item metadata, allowing any authenticated user, including Subscribers, to overwrite menu item content and settings that are rendered in the site's public navigation.

EPSS

Процентиль: 8%
0.0018
Низкий

4.3 Medium

CVSS3

Дефекты

CWE-284